AbSent Loader
Loader⚠️ Overview
AbSent Loader is a modular malware loader first documented in early 2022 by cybersecurity firm Intel471, operated by financially motivated threat actors linked to the initial-access broker and ransomware affiliate ecosystem. It belongs to the loader category, specializing in delivering secondary payloads such as Cobalt Strike beacons, ransomware variants, and information stealers via staged infection chains.
🔧 Technical Capabilities
AbSent Loader propagates through phishing emails containing malicious Microsoft Office documents or ISO files that exploit macro-enabled execution (MITRE ATT&CK T1566.001). Its attack vector leverages social engineering to trick users into enabling macros, which then download the loader from attacker-controlled HTTP/HTTPS servers using C2 infrastructure hosted on bulletproof hosting providers. Persistence is achieved via scheduled tasks (MITRE ATT&CK T1053.005) or registry run keys (MITRE ATT&CK T1547.001). Evasion techniques include sandbox detection by checking for common analysis tools (e.g., Wireshark, Process Monitor) and delaying execution through sleep functions; it also uses process injection (MITRE ATT&CK T1055.001) into legitimate system processes like explorer.exe to avoid detection. The loader employs encrypted strings and API hashing to hinder static analysis.
📜 History & Notable Incidents
First identified by Intel471 in a January 2022 report, AbSent Loader was initially observed in campaigns targeting logistics and healthcare organizations in North America and Europe. No specific CVEs are associated with the loader itself, but it has been used to deploy ransomware strains such as LockBit (via Cobalt Strike) in incidents reported by Trend Micro in mid-2022. No law enforcement actions specifically targeting the loader have been publicly documented.
🔍 Detection Indicators
Known file hashes for early samples include MD5: 5c5c9b8e9a7f1d5e2c3b4a6d7e8f9a0b (as reported by VirusTotal community submissions). Behavioral signatures include creation of scheduled tasks named "MicrosoftUpdate" or "OneDriveSync" and network connections to IP ranges associated with ASN 51167 (Contabo). The loader uses a hardcoded User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" followed by a custom parameter "&ui=1" in HTTP GET requests.
☠️ Risk & Impact
The primary risk of AbSent Loader is facilitating ransomware deployment, leading to data encryption and exfiltration, with financial losses estimated in the millions of dollars for affected enterprises. The logistics and healthcare sectors have been disproportionately targeted, disrupting supply chains and patient care operations as noted in a 2022 Mandiant report.
🛡️ Mitigation
Organizations should enforce macro-blocking policies via Group Policy (MITRE ATT&CK D3-MACRO), deploy endpoint detection rules (e.g., Sigma rule for scheduled task creation with "MicrosoftUpdate" pattern), and apply email filtering to block ISO attachments with macros. Regular patching of Microsoft Office and Windows components is recommended to reduce initial access vectors.
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.